KLA10907
Denial of service vulnerability in Apache HTTP Server
Updated: 06/01/2019
Detect date
?
12/05/2016
Severity
?
Warning
Description

An unspecified vulnerability was found in Apache HTTP Server 2.4.17 through 2.4.23. By exploiting this vulnerability malicious users can cause denial of service. This vulnerability can be exploited remotely via crafted continuation frames in a HTTP/2 request.


Technical details

Vulnerability occurs in mod_http2 module, when the Protocols configuration (including h2/h2c) does not confine length of request header. Because of that a specially crafted request can allocate memory on the sever until limit is reached.

Affected products

Apache HTTP Server from 2.4.17 to 2.4.23

Solution

For a 2.4.23 version a patch is supplied. This will be included in the next release.
Security Advisory – Apache Software Foundation

Original advisories

Apache httpd 2.4 vulnerabilities

Impacts
?
DoS 
[?]
Related products
Apache HTTP Server
CVE-IDS
?
CVE-2016-87405.0Critical